CVE-2021-27608 PUBLISHED CVSS 7.5 HIGH

An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is performed when an executable file is registered. This could further lead to complete compromise of confidentiality, Integrity and Availability.

EPSS 0.12% · 31.3th percentile

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.12%
31.3th percentile

Affected Products

VendorProductVersions
SAP SESAP Setup< 9.0
sapsetup9.0

Timeline

References

Open in Interactive Console →